← Guides·All compliance guides →
Personal Information Inventory: What You Hold, Where It Is, and Why
By Yong DuPublished
What to write down about the personal information your business holds, and the PIPEDA clause that requires it.
On this page
No Act asks for an inventory, and you still need one
There is no clause in PIPEDA, Alberta PIPA or BC PIPA that uses the words "data inventory". That wording comes from the European regulation, where Article 30 requires a record of processing activities. Canadian law does not copy it.
What Canadian law does require is narrower and easier to miss. PIPEDA Schedule 1 clause 4.2.1:
The organization shall document the purposes for which personal information is collected.
That is a shall. Section 5(2) of the Act reserves "should" for recommendations, so the distinction is deliberate and this is on the mandatory side of it. Alberta PIPA s.6(1) and BC PIPA s.5 add a separate duty to develop policies and practices for handling personal information, and a policy about information nobody has listed is a policy about nothing.
So the duty is to document purposes. An inventory is the ordinary way a small business discharges it, with the purpose written beside the thing it belongs to instead of in a separate file nobody opens.
Five later obligations read from it
This is the practical argument, and it is stronger than the legal one. The inventory is not an end in itself. It is the thing five other obligations depend on, which is why it is worth doing first rather than last.
Retention periods. You cannot decide how long to keep something you have not listed. PIPEDA Principle 5 ties retention to the purpose, so the purpose column is what sets the period.
Access requests. Someone asks what you hold about them, and the clock starts. PIPEDA s.8(3) and BC PIPA s.29(1) give you 30 days; Alberta PIPA s.28(1)(a) gives 45. The inventory is the list of places to look, and without it the answer is whatever the person handling the request happens to remember.
Breach assessment. A system is compromised at four in the afternoon. The first question is what was in it. An inventory answers that in a minute and a search of the office answers it in a day.
Service providers. Every row that names an outside system is a vendor who needs a contract term about privacy. The inventory is where that list comes from.
Your published policy. PIPEDA clause 4.8.2 requires you to make your practices available, and saying what you collect and why is the heart of it. A policy written without the inventory describes the business someone remembered, not the one that exists.
What goes in it
Six columns. Any more and it stops being maintained.
| What it is | Why you collect it | Where it lives | Who can reach it | How long you keep it | Outside parties |
|---|---|---|---|---|---|
| Patient clinical records | To provide and document treatment | Practice-management software | Dentists, hygienists, office manager | Your college sets this one, check it | Software vendor, hosted in the US |
| Patient contact and billing | To book, bill and follow up | Practice-management software | All clinical and reception staff | 7 years from last transaction | Software vendor, payment processor |
| Staff files | To manage the employment relationship | Locked cabinet, office manager | Office manager, principal dentist | 4 years after departure | None |
| Payroll | To pay staff and meet tax duties | Payroll service | Office manager | 6 years from end of tax year | Payroll provider |
| Unsuccessful job applications | To fill a vacancy | Email, HR folder | Office manager | 1 year from the decision | None |
| Mailing list | To send appointment reminders and news | Email platform | Office manager | Until the person unsubscribes | Email platform vendor |
The periods in that table are what a practice might arrive at, not figures to copy. Several of them are set by law rather than by you, and which law depends on the record and the province. Our guide on retention and destruction works through where each minimum comes from.
The "why" column is the one the Act asks for, and it is the one people fill in last and worst. "Business purposes" is not a purpose. "To book, bill and follow up" is, because you can test a retention period against it.
The "outside parties" column earns its place the first time you are asked. A client security questionnaire, an insurance renewal and a breach all ask the same question in different words: who else has this.
Two columns that catch people out
"Where it lives" means every copy, not the main one. The practice-management software is the obvious entry. The exported spreadsheet on a reception desktop, the attachment in a sent-items folder and the backup nobody has opened since the last provider are all the same personal information in three more places, and each is a place a breach can start and an access request has to reach.
"How long you keep it" has a floor as well as a ceiling in British Columbia. BC PIPA s.35(1) requires personal information used to make a decision that directly affects somebody to be kept for at least a year after the decision, and it says so "despite" the duty to destroy. The unsuccessful job application row above is the clearest example: the rejection is a decision about that person. Alberta's s.35(1) is the opposite rule, a limit rather than a floor, so a business in both provinces cannot run one practice built on the Alberta reading.
Building it in an afternoon
Do not start from a template. Start from the business, and walk it three times.
Walk the money. Every way you get paid involves a person and their details. Invoices, card payments, insurance claims, subscriptions. Each is at least one row.
Walk the people. Customers, patients or clients. Staff, past and present. Applicants who did not get the job. Contractors. Anybody who filled in a form on the website. Emergency contacts, who are usually somebody who never dealt with you at all.
Walk the systems. Open the list of software you pay for. Anything holding a name is a row, and the unglamorous ones are the ones that get missed: the booking tool, the survey you ran once, the shared drive, the camera over the till.
Then write the purpose beside each row while the reason is still fresh. That is the column the Act asks for, and it is much harder to reconstruct six months later.
Keeping it true
An inventory is only useful while it is current, and the usual failure is not that it is wrong on the day it is written. It is that nothing ever changes it.
Two triggers are enough.
Once a year, read it beside the list of software you pay for. Rows that no longer exist come out. Systems that are not in it go in.
Whenever something changes, update the row the same week. A new system, a new service provider, a new thing you collect, a service you stopped offering. This is the one that keeps it honest, and it takes a minute each time.
Date it, and name the person responsible for it. An undated inventory cannot be relied on by anybody, including you, because nobody can tell whether it describes this year or the year it was written.
What the assessment produces
ClearBreach's Compliance Readiness assessment generates a Personal Information Inventory as one of its documents, built from your own answers rather than a blank template. In the published sample for a small dental practice it runs to four sections: what this is for, the inventory itself, how to fill in each column, and keeping it current.
It arrives with the columns already set to the duties above and the rows your answers imply, so the blank parts are the ones only you can fill. You still have to walk your own business three times. Nobody can do that part for you, and a document that pretended otherwise would be worth less than the blank page.
Frequently asked questions
Does Canadian privacy law actually require a data inventory?
Not by that name. No Act uses the words 'data inventory' or 'record of processing'. What PIPEDA does require, at Schedule 1 clause 4.2.1, is that 'the organization shall document the purposes for which personal information is collected'. That is a shall, not a should. Alberta PIPA s.6(1) and BC PIPA s.5 separately require you to develop policies and practices, and you cannot write a policy about information you have not listed. An inventory is simply the ordinary way a small business satisfies the documenting duty, not an extra obligation on top of it.
How detailed does it have to be?
One row per kind of information, not one row per person or per field. A dental practice has perhaps eight rows: patient clinical records, patient contact and billing, appointment history, staff files, payroll, job applications, the mailing list, and security camera footage. A row that says 'customer records' for everything is too coarse to set a retention period against. A row for every column in your database is unusable and nobody will maintain it.
What happens if I do not have one?
Nothing happens until something else needs it, and then several things fail at once. You cannot set a retention period for information nobody has listed. You cannot answer an access request completely if you do not know everywhere the person's information sits. You cannot assess a breach quickly when you do not know what was in the affected system. In practice the inventory is discovered to be missing at the worst possible moment, which is during a breach or a regulator's enquiry.
Who should own it?
The person accountable for privacy, which PIPEDA clause 4.1 requires you to designate. Owning it means being responsible for it being current, not for filling in every row personally. The people who do the work know where the information is, so the rows get written by them and reviewed by the accountable person.
How often should it be reviewed?
Once a year as a standing review, and immediately whenever you adopt a new system that holds personal information, change a service provider, start collecting something new, or stop offering a service. The annual review is the one that catches drift. The event-driven update is the one that keeps it true.
This guide is educational and does not constitute legal advice. It is grounded in the text of PIPEDA, Alberta PIPA, and BC PIPA and published guidance from the OPC, OIPC Alberta, and OIPC BC. If your situation involves regulatory investigation, litigation risk, or circumstances not addressed here, engage a qualified privacy lawyer.
See what a compliance assessment finds
A real assessment for a small clinic: every area scored, every gap against the provision behind it, and the documents that close them.
See a complete assessment →